RHSA-2021:5108: Critical: OpenShift Container Platform 4.8.z security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value (CVE-2021-44228)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:5108?
The severity of RHSA-2021:5108 is classified as critical due to remote code execution risks associated with Log4j 2.x.
How do I fix RHSA-2021:5108?
To fix RHSA-2021:5108, update the affected log4j-core package to the latest available version that addresses the vulnerability.
What components are affected by RHSA-2021:5108?
RHSA-2021:5108 primarily affects the log4j-core library in Red Hat OpenShift Container Platform deployments.
What vulnerabilities does RHSA-2021:5108 address?
RHSA-2021:5108 addresses a remote code execution vulnerability found in Log4j 2.x when handling log messages.
Is there a workaround for RHSA-2021:5108?
While the best option is to apply the security update, temporary workarounds may include modifying logging configurations to limit exposure.